9.6
CVE-2025-12543 - Undertow-core: undertow http server fails to reject malformed host headers leading to potential cacβ¦
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rβ¦
7.5
CVE-2025-67364 -
fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functiβ¦
6.1
CVE-2025-66686 -
A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the βHelp button urlβ setting within the admin panel. The injected payload is stored and executed when any authenticaβ¦
7.5
CVE-2025-66786 -
OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface to launch a denial-of-service attack.
6.8
CVE-2025-66837 -
A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware
7.5
CVE-2025-67366 -
@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism:β¦
6.5
CVE-2025-61489 -
A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.
8.8
CVE-2026-0628 - Privilege Escalation via Malicious Extension in Chrome's WebView Tag
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
6.9
CVE-2026-0643 - projectworlds House Rental and Property Listing Signup register.php unrestricted upload
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The explβ¦
7.8
CVE-2025-47396 - Double Free in Graphics
Memory corruption occurs when a secure application is launched on a device with insufficient memory.